CVE Vulnerabilities

CVE-2025-55074

Published: Nov 18, 2025 | Modified: Nov 25, 2025
CVSS 3.x
3.5
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channels via channel member objects

Affected Software

Name Vendor Start Version End Version
Mattermost_server Mattermost 10.5.0 (including) 10.5.12 (excluding)
Mattermost_server Mattermost 10.11.0 (including) 10.11.4 (excluding)

References